Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 1 | /* |
| 2 | * Copyright 2002-2004, Instant802 Networks, Inc. |
| 3 | * Copyright 2005, Devicescape Software, Inc. |
| 4 | * |
| 5 | * This program is free software; you can redistribute it and/or modify |
| 6 | * it under the terms of the GNU General Public License version 2 as |
| 7 | * published by the Free Software Foundation. |
| 8 | */ |
| 9 | |
| 10 | #ifndef IEEE80211_KEY_H |
| 11 | #define IEEE80211_KEY_H |
| 12 | |
| 13 | #include <linux/types.h> |
Johannes Berg | 8f37171 | 2007-08-28 17:01:54 -0400 | [diff] [blame] | 14 | #include <linux/list.h> |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 15 | #include <linux/crypto.h> |
Johannes Berg | db4d116 | 2008-02-25 16:27:45 +0100 | [diff] [blame] | 16 | #include <linux/rcupdate.h> |
Ard Biesheuvel | 5fdb373 | 2019-06-12 18:19:54 +0200 | [diff] [blame] | 17 | #include <crypto/arc4.h> |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 18 | #include <net/mac80211.h> |
| 19 | |
Johannes Berg | e31b821 | 2010-10-05 19:39:30 +0200 | [diff] [blame] | 20 | #define NUM_DEFAULT_KEYS 4 |
| 21 | #define NUM_DEFAULT_MGMT_KEYS 2 |
Alexander Wetzel | 96fc6ef | 2019-03-19 21:34:08 +0100 | [diff] [blame] | 22 | #define INVALID_PTK_KEYIDX 2 /* Keyidx always pointing to a NULL key for PTK */ |
Johannes Berg | e31b821 | 2010-10-05 19:39:30 +0200 | [diff] [blame] | 23 | |
Johannes Berg | 11a843b | 2007-08-28 17:01:55 -0400 | [diff] [blame] | 24 | struct ieee80211_local; |
| 25 | struct ieee80211_sub_if_data; |
| 26 | struct sta_info; |
| 27 | |
Johannes Berg | db4d116 | 2008-02-25 16:27:45 +0100 | [diff] [blame] | 28 | /** |
| 29 | * enum ieee80211_internal_key_flags - internal key flags |
| 30 | * |
| 31 | * @KEY_FLAG_UPLOADED_TO_HARDWARE: Indicates that this key is present |
| 32 | * in the hardware for TX crypto hardware acceleration. |
Johannes Berg | 95acac6 | 2011-07-12 12:30:59 +0200 | [diff] [blame] | 33 | * @KEY_FLAG_TAINTED: Key is tainted and packets should be dropped. |
Cedric Izoard | c7ef38e | 2015-03-17 10:47:33 +0000 | [diff] [blame] | 34 | * @KEY_FLAG_CIPHER_SCHEME: This key is for a hardware cipher scheme |
Johannes Berg | db4d116 | 2008-02-25 16:27:45 +0100 | [diff] [blame] | 35 | */ |
| 36 | enum ieee80211_internal_key_flags { |
| 37 | KEY_FLAG_UPLOADED_TO_HARDWARE = BIT(0), |
Johannes Berg | 95acac6 | 2011-07-12 12:30:59 +0200 | [diff] [blame] | 38 | KEY_FLAG_TAINTED = BIT(1), |
Cedric Izoard | c7ef38e | 2015-03-17 10:47:33 +0000 | [diff] [blame] | 39 | KEY_FLAG_CIPHER_SCHEME = BIT(2), |
Johannes Berg | db4d116 | 2008-02-25 16:27:45 +0100 | [diff] [blame] | 40 | }; |
Johannes Berg | 11a843b | 2007-08-28 17:01:55 -0400 | [diff] [blame] | 41 | |
gregor kowski | ca99861 | 2009-12-09 23:25:05 +0100 | [diff] [blame] | 42 | enum ieee80211_internal_tkip_state { |
| 43 | TKIP_STATE_NOT_INIT, |
| 44 | TKIP_STATE_PHASE1_DONE, |
| 45 | TKIP_STATE_PHASE1_HW_UPLOADED, |
| 46 | }; |
| 47 | |
Harvey Harrison | b0f76b3 | 2008-05-14 16:26:19 -0700 | [diff] [blame] | 48 | struct tkip_ctx { |
Johannes Berg | 523b02e | 2011-07-07 22:28:01 +0200 | [diff] [blame] | 49 | u16 p1k[5]; /* p1k cache */ |
| 50 | u32 p1k_iv32; /* iv32 for which p1k computed */ |
gregor kowski | ca99861 | 2009-12-09 23:25:05 +0100 | [diff] [blame] | 51 | enum ieee80211_internal_tkip_state state; |
Harvey Harrison | b0f76b3 | 2008-05-14 16:26:19 -0700 | [diff] [blame] | 52 | }; |
| 53 | |
Eliad Peller | f8079d4 | 2016-02-14 13:56:35 +0200 | [diff] [blame] | 54 | struct tkip_ctx_rx { |
| 55 | struct tkip_ctx ctx; |
| 56 | u32 iv32; /* current iv32 */ |
| 57 | u16 iv16; /* current iv16 */ |
| 58 | }; |
| 59 | |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 60 | struct ieee80211_key { |
Johannes Berg | 11a843b | 2007-08-28 17:01:55 -0400 | [diff] [blame] | 61 | struct ieee80211_local *local; |
| 62 | struct ieee80211_sub_if_data *sdata; |
| 63 | struct sta_info *sta; |
| 64 | |
Johannes Berg | 3b96766 | 2008-04-08 17:56:52 +0200 | [diff] [blame] | 65 | /* for sdata list */ |
Johannes Berg | 11a843b | 2007-08-28 17:01:55 -0400 | [diff] [blame] | 66 | struct list_head list; |
| 67 | |
Johannes Berg | ad0e2b5 | 2010-06-01 10:19:19 +0200 | [diff] [blame] | 68 | /* protected by key mutex */ |
Johannes Berg | 11a843b | 2007-08-28 17:01:55 -0400 | [diff] [blame] | 69 | unsigned int flags; |
| 70 | |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 71 | union { |
| 72 | struct { |
Johannes Berg | 523b02e | 2011-07-07 22:28:01 +0200 | [diff] [blame] | 73 | /* protects tx context */ |
| 74 | spinlock_t txlock; |
| 75 | |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 76 | /* last used TSC */ |
Harvey Harrison | b0f76b3 | 2008-05-14 16:26:19 -0700 | [diff] [blame] | 77 | struct tkip_ctx tx; |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 78 | |
| 79 | /* last received RSC */ |
Eliad Peller | f8079d4 | 2016-02-14 13:56:35 +0200 | [diff] [blame] | 80 | struct tkip_ctx_rx rx[IEEE80211_NUM_TIDS]; |
Saravana | b98ea05 | 2012-12-04 19:47:42 +0530 | [diff] [blame] | 81 | |
| 82 | /* number of mic failures */ |
| 83 | u32 mic_failures; |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 84 | } tkip; |
| 85 | struct { |
Jouni Malinen | 9190252 | 2010-06-11 10:27:33 -0700 | [diff] [blame] | 86 | /* |
| 87 | * Last received packet number. The first |
Johannes Berg | 5a306f5 | 2012-11-14 23:22:21 +0100 | [diff] [blame] | 88 | * IEEE80211_NUM_TIDS counters are used with Data |
Jouni Malinen | 9190252 | 2010-06-11 10:27:33 -0700 | [diff] [blame] | 89 | * frames and the last counter is used with Robust |
| 90 | * Management frames. |
| 91 | */ |
Johannes Berg | 4325f6c | 2013-05-08 13:09:08 +0200 | [diff] [blame] | 92 | u8 rx_pn[IEEE80211_NUM_TIDS + 1][IEEE80211_CCMP_PN_LEN]; |
Ard Biesheuvel | 7ec7c4a | 2013-10-10 09:55:20 +0200 | [diff] [blame] | 93 | struct crypto_aead *tfm; |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 94 | u32 replays; /* dot11RSNAStatsCCMPReplays */ |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 95 | } ccmp; |
Jouni Malinen | 765cb46 | 2009-01-08 13:32:01 +0200 | [diff] [blame] | 96 | struct { |
Johannes Berg | 4325f6c | 2013-05-08 13:09:08 +0200 | [diff] [blame] | 97 | u8 rx_pn[IEEE80211_CMAC_PN_LEN]; |
Ard Biesheuvel | 2671782 | 2017-02-06 10:49:28 +0000 | [diff] [blame] | 98 | struct crypto_shash *tfm; |
Jouni Malinen | 765cb46 | 2009-01-08 13:32:01 +0200 | [diff] [blame] | 99 | u32 replays; /* dot11RSNAStatsCMACReplays */ |
| 100 | u32 icverrors; /* dot11RSNAStatsCMACICVErrors */ |
Jouni Malinen | 765cb46 | 2009-01-08 13:32:01 +0200 | [diff] [blame] | 101 | } aes_cmac; |
Max Stepanov | 2475b1cc | 2013-03-24 14:23:27 +0200 | [diff] [blame] | 102 | struct { |
Jouni Malinen | 8ade538 | 2015-01-24 19:52:09 +0200 | [diff] [blame] | 103 | u8 rx_pn[IEEE80211_GMAC_PN_LEN]; |
| 104 | struct crypto_aead *tfm; |
| 105 | u32 replays; /* dot11RSNAStatsCMACReplays */ |
| 106 | u32 icverrors; /* dot11RSNAStatsCMACICVErrors */ |
| 107 | } aes_gmac; |
| 108 | struct { |
Jouni Malinen | 00b9cfa | 2015-01-24 19:52:06 +0200 | [diff] [blame] | 109 | /* Last received packet number. The first |
| 110 | * IEEE80211_NUM_TIDS counters are used with Data |
| 111 | * frames and the last counter is used with Robust |
| 112 | * Management frames. |
| 113 | */ |
| 114 | u8 rx_pn[IEEE80211_NUM_TIDS + 1][IEEE80211_GCMP_PN_LEN]; |
| 115 | struct crypto_aead *tfm; |
| 116 | u32 replays; /* dot11RSNAStatsGCMPReplays */ |
| 117 | } gcmp; |
| 118 | struct { |
Max Stepanov | 2475b1cc | 2013-03-24 14:23:27 +0200 | [diff] [blame] | 119 | /* generic cipher scheme */ |
Johannes Berg | a31cf1c | 2015-04-20 18:21:58 +0200 | [diff] [blame] | 120 | u8 rx_pn[IEEE80211_NUM_TIDS + 1][IEEE80211_MAX_PN_LEN]; |
Max Stepanov | 2475b1cc | 2013-03-24 14:23:27 +0200 | [diff] [blame] | 121 | } gen; |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 122 | } u; |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 123 | |
Jiri Benc | e9f207f | 2007-05-05 11:46:38 -0700 | [diff] [blame] | 124 | #ifdef CONFIG_MAC80211_DEBUGFS |
| 125 | struct { |
| 126 | struct dentry *stalink; |
| 127 | struct dentry *dir; |
Johannes Berg | d9c58f3 | 2008-04-08 16:46:36 -0400 | [diff] [blame] | 128 | int cnt; |
Jiri Benc | e9f207f | 2007-05-05 11:46:38 -0700 | [diff] [blame] | 129 | } debugfs; |
| 130 | #endif |
| 131 | |
Johannes Berg | 8f20fc2 | 2007-08-28 17:01:54 -0400 | [diff] [blame] | 132 | /* |
| 133 | * key config, must be last because it contains key |
| 134 | * material as variable length member |
| 135 | */ |
| 136 | struct ieee80211_key_conf conf; |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 137 | }; |
| 138 | |
Max Stepanov | 2475b1cc | 2013-03-24 14:23:27 +0200 | [diff] [blame] | 139 | struct ieee80211_key * |
| 140 | ieee80211_key_alloc(u32 cipher, int idx, size_t key_len, |
| 141 | const u8 *key_data, |
| 142 | size_t seq_len, const u8 *seq, |
| 143 | const struct ieee80211_cipher_scheme *cs); |
Johannes Berg | db4d116 | 2008-02-25 16:27:45 +0100 | [diff] [blame] | 144 | /* |
| 145 | * Insert a key into data structures (sdata, sta if necessary) |
Johannes Berg | 79cf2df | 2013-03-06 22:53:52 +0100 | [diff] [blame] | 146 | * to make it used, free old key. On failure, also free the new key. |
Johannes Berg | db4d116 | 2008-02-25 16:27:45 +0100 | [diff] [blame] | 147 | */ |
Johannes Berg | 79cf2df | 2013-03-06 22:53:52 +0100 | [diff] [blame] | 148 | int ieee80211_key_link(struct ieee80211_key *key, |
| 149 | struct ieee80211_sub_if_data *sdata, |
| 150 | struct sta_info *sta); |
Alexander Wetzel | 96fc6ef | 2019-03-19 21:34:08 +0100 | [diff] [blame] | 151 | int ieee80211_set_tx_key(struct ieee80211_key *key); |
Johannes Berg | 3b8d9c2 | 2013-03-06 22:58:23 +0100 | [diff] [blame] | 152 | void ieee80211_key_free(struct ieee80211_key *key, bool delay_tailroom); |
Johannes Berg | 79cf2df | 2013-03-06 22:53:52 +0100 | [diff] [blame] | 153 | void ieee80211_key_free_unused(struct ieee80211_key *key); |
Johannes Berg | f7e0104 | 2010-12-09 19:49:02 +0100 | [diff] [blame] | 154 | void ieee80211_set_default_key(struct ieee80211_sub_if_data *sdata, int idx, |
| 155 | bool uni, bool multi); |
Jouni Malinen | 3cfcf6ac | 2009-01-08 13:32:02 +0200 | [diff] [blame] | 156 | void ieee80211_set_default_mgmt_key(struct ieee80211_sub_if_data *sdata, |
| 157 | int idx); |
Johannes Berg | 7907c7d | 2013-12-04 23:47:09 +0100 | [diff] [blame] | 158 | void ieee80211_free_keys(struct ieee80211_sub_if_data *sdata, |
| 159 | bool force_synchronize); |
Johannes Berg | 6d10e46 | 2013-03-06 23:09:11 +0100 | [diff] [blame] | 160 | void ieee80211_free_sta_keys(struct ieee80211_local *local, |
| 161 | struct sta_info *sta); |
Johannes Berg | 11a843b | 2007-08-28 17:01:55 -0400 | [diff] [blame] | 162 | void ieee80211_enable_keys(struct ieee80211_sub_if_data *sdata); |
Michal Kazior | f9dca80 | 2015-05-13 09:16:48 +0000 | [diff] [blame] | 163 | void ieee80211_reset_crypto_tx_tailroom(struct ieee80211_sub_if_data *sdata); |
Johannes Berg | 11a843b | 2007-08-28 17:01:55 -0400 | [diff] [blame] | 164 | |
Johannes Berg | 40b275b | 2011-05-13 14:15:49 +0200 | [diff] [blame] | 165 | #define key_mtx_dereference(local, ref) \ |
| 166 | rcu_dereference_protected(ref, lockdep_is_held(&((local)->key_mtx))) |
| 167 | |
Johannes Berg | 8d1f7ec | 2013-02-23 00:59:03 +0100 | [diff] [blame] | 168 | void ieee80211_delayed_tailroom_dec(struct work_struct *wk); |
| 169 | |
Jiri Benc | f0706e8 | 2007-05-05 11:45:53 -0700 | [diff] [blame] | 170 | #endif /* IEEE80211_KEY_H */ |